Skip to content

Malware

Regin

Regin is a sophisticated malware and hacking toolkit attributed to United Kingdom' Government Communications Headquarters (GCHQ) for government spying operations.

Regin is a Windows malware family.

Background

Regin is an advanced malware platform and intrusion toolkit linked to the United Kingdom's Government Communications Headquarters (GCHQ) and used for state-level espionage. Its existence was first made public in November 2014 by Kaspersky Lab, Symantec, and The Intercept. The malware struck targets across several sectors, including telecommunications, government, and financial institutions. Its architecture is modular, and dozens of distinct modules have since been uncovered and tied to the family. Symantec counted roughly 100 infections spread across 10 countries, affecting private firms, government bodies, and research institutions alike.


Source: Malpedia (Fraunhofer FKIE).